Researchers Warn 3 Apps Have Been Stealing Crypto Undetected For A Year
Three crypto based apps have concealed a nasty surprise for those that have downloaded them. Researchers Warn 3 Apps Have Been Stealing Crypto Undetected For A Year
Cyber security researchers have discovered a year-long malware operation that has targeted cryptocurrency users with the creation of a number of fake apps.
Security firm Intezer Labs warned that ever increasing crypto prices have created heightened activity among hackers and malicious actors seeking financial gains. The malware has been disseminated over the past year, but was only discovered in December 2020.
The new remote access trojan (RAT), dubbed ElectroRAT, has been used to empty the cryptocurrency wallets of thousands of Windows, macOS, and Linux users, the report added.
Three cryptocurrency-related apps deployed in the attack — Jamm, eTrade/Kintum, and DaoPoker — were all hosted on their own websites. The first two are bogus crypto trading apps while the third is gambling based.
The ElectroRAT malware hidden inside these apps is extremely intrusive according to the researchers;
“It has various capabilities such as keylogging, taking screenshots, uploading files from disk, downloading files, and executing commands on the victim’s console.”
After being launched on a victim’s computer, the apps show a foreground user interface designed to divert attention from the malicious background processes. The apps were promoted using social media platforms Twitter and Telegram in addition to cryptocurrency based forums such as Bitcointalk.
Intezer Labs estimated that the campaign has already infected “thousands of victims” who have had their crypto wallets emptied. It added that there was evidence that some victims who were compromised by the apps were using popular crypto wallets such as MetaMask.
The malware has been written in a multi-platform programming language called Golang which makes it harder to detect. The security firm stated that it was uncommon to see a RAT designed to steal personal information from cryptocurrency users that was written from scratch, adding;
“It is even rarer to see such a wide-ranging and targeted campaign that includes various components such as fake apps and websites, and marketing/promotional efforts via relevant forums and social media.”
There have been a number of cases in 2020 where fake versions of legitimate apps and browser extensions such as MetaMask or Ledger have made their way onto victims computers. This may be related to Ledger’s massive data breach in mid-December.
In September 2020, Coinbase users were among the victims of new Android-based malware disseminated through Google Play Store.
Researchers Warn 3 Apps,Researchers Warn 3 Apps,Researchers Warn 3 Apps,Researchers Warn 3 Apps,Researchers Warn 3 Apps,
Related Articles:
The Pandemic Turbocharged Online Privacy Concerns
US Treasury Breached By Foreign-Backed Hackers
FireEye Hack Portends A Scary Era Of Cyber-Insecurity
How FinCEN Became A Honeypot For Sensitive Personal Data
Apple And Google To Stop X-Mode From Collecting Location Data From Users’ Phones
Surge In Physical Threats During Pandemic Complicates Employee Security Efforts
Imagine A Nutrition Label—for Cybersecurity
Cybercriminals Attack GoDaddy-based Cryptocurrency Platforms
Biden Team Lacks Full U.S. Cybersecurity Support In Transition Fracas
Nasdaq To Buy Anti-Financial Crime Firm Verafin For $2.75 Billion
Mysterious Software Bugs Were Used To Hack iPhones and Android Phones and No One Will Talk About It
Dark Web Hackers Say They Hold Keys To 10,000 Robinhood Accounts #GotBitcoin
Hackers Steal $2.3 Million From Trump Wisconsin Campaign Account
Crypto Scammers Deface Trump Campaign Website One Week From Elections
Telecoms Protocol From 1975 Exploited To Target 20 Crypto Executives
With Traders Far From Offices, Banks Bring Surveillance To Homes
A Millionaire Hacker’s Lessons For Corporate America
Container Shipping Line CMA CGM Says Data Possibly Stolen In Cyberattack
Major Hospital System Hit With Cyberattack, Potentially Largest In U.S. History
Hacker Releases Information On Las Vegas-Area Students After Officials Don’t Pay Ransom
Russian Troll Farms Posing As African-American Support For Donald Trump
US Moves To Seize Cryptocurrency Accounts Linked To North Korean Heists
These Illicit SIM Cards Are Making Hacks Like Twitter’s Easier
Uber Exec Allegedly Concealed 2016 Hack With $100K BTC ‘Bug Bounty’ Pay-Off
Senate Panel’s Russia Probe Found Counterintelligence Risks In Trump’s 2016 Campaign
Bockchain Based Surveillance Camera Technology Detects Crime In Real-Time
Facebook Offers Money To Reel In TikTok Creators
How A Facebook Employee Helped Trump Win—But Switched Sides For 2020
Facebook Rebuffs Barr, Moves Ahead on Messaging Encryption
Facebook Ad Rates Fall As Coronavirus Undermines Ad Spending
Facebook Labels Trump Posts On Grounds That He’s Inciting Violence
Crypto Prediction Markets Face Competition From Facebook ‘Forecasts’ (#GotBitcoin?)
Coronavirus Is The Pin That Burst Facebook And Google Online Ads Business Bubble
OpenLibra Plans To Launch Permissionless Fork Of Facebook’s Stablecoin (#GotBitcoin?)
Facebook Warns Investors That Libra Stablecoin May Never Launch (#GotBitcoin?)
FTC Approves Roughly $5 Billion Facebook Settlement (#GotBitcoin?)
How Facebook Coin’s Big Corporate Backers Will Profit From Crypto
Facebook’s Libra Is Bad For African Americans (#GotBitcoin?)
A Monumental Fight Over Facebook’s Cryptocurrency Is Coming (#GotBitcoin?)
Alert! 540 Million Facebook Users’ Data Exposed On Amazon Servers (#GotBitcoin?)
Facebook Bug Potentially Exposed Unshared Photos of Up 6.8 Million Users (#GotBitcoin?)
Facebook Says Millions of Users’ Passwords Were Improperly Stored in Internal Systems (#GotBitcoin?)
Advertisers Allege Facebook Failed to Disclose Key Metric Error For More Than A Year (#GotBitcoin?)
Ad Agency CEO Calls On Marketers To Take Collective Stand Against Facebook (#GotBitcoin?)
Thieves Can Now Nab Your Data In A Few Minutes For A Few Bucks (#GotBitcoin?)
New Crypto Mining Malware Beapy Uses Leaked NSA Hacking Tools: Symantec Research (#GotBitcoin?)
Equifax, FICO Team Up To Sell Your Financial Data To Banks (#GotBitcoin?)
Cyber-Security Alert!: FEMA Leaked Data Of 2.3 Million Disaster Survivors (#GotBitcoin?)
DMV Hacked! Your Personal Records Are Now Being Transmitted To Croatia (#GotBitcoin?)
Lithuanian Man Pleads Guilty In $100 Million Fraud Against Google, Facebook (#GotBitcoin?)
Hack Alert! Buca Di Beppo, Owned By Earl Enterprises Suffers Data Breach Of 2M Cards (#GotBitcoin?)
SEC Hack Proves Bitcoin Has Better Data Security (#GotBitcoin?)
Maxine Waters (D., Calif.) Rises As Banking Industry’s Overseer (#GotBitcoin?)
Leave a Reply
You must be logged in to post a comment.